About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



5 Eur. Data Prot. L. Rev. 352 (2019)
Privacy Icons: A Risk-Based Approach to Visualisation of Data Processing

handle is hein.journals/edpl5 and id is 380 raw text is: 


352   | Privacy Icons


Privacy Icons:

       A   Risk-Based Approach to Visualisation of Data Processing

       Zohar  Efroni, Jakob  Metzger,  Lena Mischau   and  Marie  Schirmbeck*

       Although   the institution of consent  within the General  Data  Protection  Regulation  intends
       tofacilitate  the exercise of personal  autonomy,   reality paints a different picture. Due  to a
       host  of structural and  psychological  deficits, the process of giving consent  is often neither
       informed   nor does itfoster self-determination.  One key  element in addressing  this shortcom-
       ing  is the visualisation of relevant information   through  icons. This  article outlines a risk-
       based   methodology   for the selection, design  and  implementation   of such  privacy  icons. It
       lays  the groundworkfor identifying risky data processing aspects as afirst step in a larger
       project  of creating a privacy  icons set to accompany   privacy  policies. The ultimate  goal of
       the privacy  icons is to assist users in making better informed   consent decisions  through  the
       visualisation  of data processing  aspects  based  on their inherent risks.



       Keywords:   Privacy  Icons, Consent, Risk-Based   Approach,  Private Autonomy, Legal Design


1. Introduction

1. The   Problem

Internet users are being routinely asked to grant their
consent to the collection and use of personal informa-
tion in connection  with gaining access to goods  and
services. Very often, 'data subjects' in terms of data
protection law  are at the same  time  'consumers'  in
terms of consumer   protection law. In many cases, ob-
taining consent  is necessary for legitimising the use
of personal data.' In order to be valid, the consent must
be 'informed.2  Many   studies have shown,   however,
that users often do not read privacy policies they grant


    DOI: 10.21552/edpl/2019/3/9
    Dr Zohar Efroni, LLM, Research Group Lead at the Weizenbaum
    Institute for the Networked Society in Berlin; Humboldt University
    Law Faculty, Berlin.Jakob Metzger, Research Associate at the
    Weizenbaum Institute for the Networked Society in Berlin; Doctoral
    Candidate, Humboldt University Law Faculty, Berlin. Lena Mischau,
    Research Associate at the Weizenbaum Institute for the Networked
    Society in Berlin; Doctoral Candidate, Humboldt University Law
    Faculty, Berlin. Marie Schirmbeck, MSc Psychology, Research
    Associate at the Weizenbaum Institute for the Networked Society in
    Berlin;Humboldt University Law Faculty, Berlin. This work has
    been funded by the Federal Ministry of Education and Research of
    Germany(BMBF) under grantno 16D    ('Deutsches Internet-
    Institut'). For correspondence: <zohar.efroni@rewi.hu-berlin.de>.
1   Alongside consent, which is at the focus of this article, alternative
    legal grounds (such as the legitimate interests of the controller or


their consent to. Due to a host of structural conditions
and  cognitive deficiencies, the  consent granted  by
checking  a box that merely provides  a link to the full
text of the privacy  policy might  not  qualify as in-
formed. One  of the keyreasons for thelackof informed
consent  is that users fail to properly evaluate or even
recognise  the risks (or the potential negative conse-
quences)4  involved in the processing of their data.



2. Motivation and Structure of the Article

This  article is part of a five-phased  privacy icons
project in which we  inquire whether  visualisation of


    complying with legal obligations) may justify data processing
    independently of the individual wish of the data subject.
2   art 4(11) GDPR (consent' of the data subject means any freely
    given, specific, informed and unambiguous indication of the
    data subject's wishes by which he or she, by a statement or by a
    clear affirmative action, signifies agreement to the processing of
    personal data relating to him or her').
3   Daniel J Solove, 'Privacy Self-Management and the Consent
    Dilemma' (2013) 126 Harv L Rev 1880.
4   In this article, we use the terms 'risk' and 'possible negative
    consequences' interchangeably while keeping inmindthat
    negative consequence tothe interestsofagiven ser inagiven
    consent situation are very hard to predict and estimate ex ante.
    We elaborate on the notion of risk in the context of data protec-
    tion law in s V. below.


EDPL  3|2019